GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
88 advisories
Filter by severity
Nervos CKB vulnerable to low-resource flood DDoS attacks through network message
Low
GHSA-p2gm-ffr3-w2xw
was published
for
ckb
(Rust)
Feb 8, 2023
Nervos CKB calculation of program load cycles may be missed when executing in resume mode
Low
GHSA-fjj4-2q73-jvgc
was published
for
ckb
(Rust)
Feb 8, 2023
`tokio::io::ReadHalf<T>::unsplit` is Unsound
Low
GHSA-4q83-7cq4-p6wg
was published
for
tokio
(Rust)
Feb 4, 2023
linux-loader reading beyond EOF could lead to infinite loop
Low
CVE-2022-23523
was published
for
linux-loader
(Rust)
Dec 12, 2022
Tauri Filesystem Scope can be Partially Bypassed
Low
CVE-2022-41874
was published
for
Tauri
(Rust)
Nov 8, 2022
personnummer/rust vulnerable to Improper Input Validation
Low
GHSA-28r9-pq4c-wp3c
was published
for
personnummer
(Rust)
Sep 21, 2022
ansi_term is Unmaintained
Low
GHSA-74w3-p89x-ffgh
was published
for
ansi_term
(Rust)
Sep 16, 2022
•
withdrawn
Cargo extracting malicious crates can corrupt arbitrary files
Low
CVE-2022-36113
was published
for
cargo
(Rust)
Sep 16, 2022
Threshold value is ignored (all shares are n=3)
Low
GHSA-978j-88f3-p5j3
was published
for
shamir
(Rust)
Jun 17, 2022
Exposure of Resource to Wrong Sphere in Simple-Wayland-HotKey-Daemon
Low
CVE-2022-27814
was published
for
Simple-Wayland-HotKey-Daemon
(Rust)
Apr 15, 2022
Chrono has potential segfault issue in SPIFFE authenticator
Low
GHSA-45w3-v3g4-54pm
was published
for
parsec-service
(Rust)
Feb 11, 2022
Lenient Parsing of Content-Length Header When Prefixed with Plus Sign
Low
CVE-2021-32715
was published
for
hyper
(Rust)
Jul 12, 2021
ProTip!
Advisories are also available from the
GraphQL API